DaST: Data-Free Substitute Training for Adversarial Attacks
Mingyi Zhou, Jing Wu, Yipeng Liu, Shuaicheng Liu, Ce Zhu
Abstract
Machine learning models are vulnerable to adversarial examples. For the black-box setting, current substitute attacks need pre-trained models to generate adversarial examples. However, pre-trained models are hard to obtain in real-world tasks. In this paper, we propose a data-free substitute training method (DaST) to obtain substitute models for adversarial black-box attacks without the requirement of any real data. To achieve this, DaST utilizes specially designed generative adversarial networks (GANs) to train the substitute models. In particular, we design a multi-branch architecture and label-control loss for the generative model to deal with the uneven distribution of synthetic samples. The substitute model is then trained by the synthetic samples generated by the generative model, which are labeled by the attacked model subsequently. The experiments demonstrate the substitute models produced by DaST can achieve competitive performance compared with the baseline models which are trained by the same train set with attacked models. Additionally, to evaluate the practicability of the proposed method on the real-world task, we attack an online machine learning model on the Microsoft Azure platform. The remote model misclassifies 98.35% of the adversarial examples crafted by our method. To the best of our knowledge, we are the first to train a substitute model for adversarial attacks without any real data. Our codes are publicly available 1 .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers37
- Parallel Rectangle Flip Attack: A Query-based Black-box Attack against Object DetectionSiyuan Liang, Baoyuan Wu, Yanbo Fan, Xingxing Wei et al.ICCV 2021 · 100 citations
- Adv-Attribute: Inconspicuous and Transferable Adversarial Attack on Face RecognitionShuai Jia, Bangjie Yin, Taiping Yao, Shouhong Ding et al.NeurIPS 2022 · 84 citations
- Learning with Noisy Labels via Sparse RegularizationXiong Zhou, Xianming Liu, Chenyang Wang, Deming Zhai et al.ICCV 2021 · 77 citations
- Towards Data-Free Model Stealing in a Hard Label SettingSunandini Sanyal, Sravanti Addepalli, R. Venkatesh BabuCVPR 2022 · 76 citations
- Practical No-box Adversarial Attacks against DNNsQizhang Li, Yiwen Guo, Hao ChenNeurIPS 2020 · 73 citations
Builds on4
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Stealing Machine Learning Models via Prediction APIsFlorian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter et al.USENIX Security 2016 · 2,088 citations
- MagNet: A Two-Pronged Defense against Adversarial ExamplesDongyu Meng, Hao ChenCCS 2017 · 1,295 citations
- HopSkipJumpAttack: A Query-Efficient Decision-Based AttackJianbo Chen, Michael I. Jordan, Martin J. WainwrightS&P 2020 · 797 citations
Related papers
- Towards Efficient Data Free Blackbox Adversarial AttackJie Zhang, Bo Li, Jianghe Xu, Shuang Wu et al.CVPR 2022 · 52 citations
- DST: Dynamic Substitute Training for Data-free Black-box AttackWenxuan Wang, Xuelin Qian, Yanwei Fu, Xiangyang XueCVPR 2022 · 18 citations
- Delving into Data: Effectively Substitute Training for Black-box AttackWenxuan Wang, Bangjie Yin, Taiping Yao, Li Zhang et al.CVPR 2021
- KOEnsAttack: Towards Efficient Data-Free Black-Box Adversarial Attacks via Knowledge-Orthogonalized Substitute EnsemblesChaoyong Yang, Jia-Li Yin, Bin Chen, Zhaozhe Hu et al.ICCV 2025
- Alchemy: Data-Free Adversarial TrainingYijie Bai, Zhongming Ma, Yanjiao Chen, Jiangyi Deng et al.CCS 2024
